CVE-2025-58162

MEDIUM

Mobile Security Framework 4.4.0 - Authenticated Path Traversal and Arbitrary File Write via Malicious APK Upload

Title source: llm
STIX 2.1

Description

MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1.

Scores

CVSS v3 6.5
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
opensecurity/mobile_security_framework 4.4.0
pypi/mobsf 0 - 4.4.1PyPI
Published Sep 02, 2025
Tracked Since Feb 18, 2026